Splunk Search

New to Splunk and its alternatives

xracerx
New Member

Hi there,

How is it possible to analyze windows log, lotus notes file and sample sap log files in the system. The purpose is to review admin and activity logs privileges in the system.

Is there other alternatives like sawmill and what can it do?

Any advice is much appreciated.

Tags (1)
0 Karma

splunker12er
Motivator

To analyze Windows logs , I would suggest you to install 'Splunk universal forwarder' (http://www.splunk.com/en_us/download/universal-forwarder.html#) choose your os version and type appropriately.

Continue the installation , and it prompts you to monitor for several logs, files , etc.

Configuration , Installation , forwarding, receiving, docs - FYR

http://docs.splunk.com/Documentation/Splunk/6.2.3/Forwarding/Setupforwardingandreceiving
http://docs.splunk.com/Documentation/Splunk/6.2.3/Forwarding/Configureforwarderswithoutputs.confd
http://docs.splunk.com/Documentation/Splunk/6.2.3/Updating/Exampleaddaninputtoforwarders

xracerx
New Member

Hi,

to be exact I am trying to analyze this type of log files.(File Server & Windows CPRS Log)

Level   Date and Time   Source  Event ID    Task Category
Information 10-Feb-15 11:02:17 AM   Microsoft-Windows-Security-Auditing 4780    User Account Management "The ACL was set on accounts which are members of administrators groups.


Subject:
    Security ID:        ANONYMOUS LOGON
    Account Name:       ANONYMOUS LOGON
    Account Domain:     NT AUTHORITY
    Logon ID:       0x3e6

Target Account:
    Security ID:        CISCODOMAIN\IS Account Operators
    Account Name:       IS Account Operators
    Account Domain:     DC=ciscodomain,DC=local

Any advise?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...